
CYBERJAYA, Aug 29 — In the nearly 30 years since Malaysia began developing its national cyber emergency response capabilities with the establishment of MyCERT, the most significant change has been not merely the growing volume of cyber threats, but the speed at which attacks can occur, now further accelerated by artificial intelligence (AI).
Telekom Malaysia Chief Information Security Officer Raja Azrina Raja Othman, who was among the co-founders of MyCERT in 1997, said cyber threats three decades ago were largely confined to specific systems and networks.
Today, however, almost all services operate digitally and are interconnected, ranging from banking and government services to corporate operations and national critical infrastructure.
“When a cyberattack occurs, the impact goes beyond mere system downtime. It can compromise operations, finances, customer data and reputation, as well as disrupt services relied upon by the public,” she said in a special interview held in conjunction with the recent launch of TM’s 80th-anniversary celebrations, officiated by Prime Minister Datuk Seri Anwar Ibrahim.
She added that another major shift was the sheer speed at which cyberattacks could now be launched, with AI further accelerating the process.
“With AI, cyber attackers can more easily identify vulnerabilities, craft more convincing phishing campaigns and launch attacks at a much faster pace.
“Cyber attackers today operate rapidly with the aid of AI. Therefore, cyber defence strategies can no longer rely solely on manual processes,” she said.
Raja Azrina said the real challenge lies in increasingly complex information infrastructures driven by extensive application integration.
A lack of alignment between IT planning and information security could increase an organisation’s exposure to cyber threats, she said.
However, she observed that some organisations still viewed cybersecurity as an optional measure rather than an essential component of their operations.
“In reality, cybersecurity is a matter of risk management and business continuity. If core systems are compromised, can the organisation continue to operate? Can we maintain service delivery to customers? And will they retain confidence in our business?
“These are the questions organisations must address,” she added.
Therefore, she said, responsibility for cybersecurity must start with leadership and be embedded within organisational governance.
She stressed that cybersecurity investments should be guided by a risk-based approach, with organisations prioritising risks according to their potential impact on business operations.
“Even with cybersecurity investments, we cannot assume that attacks can be prevented entirely. Instead, we must be prepared for the possibility that an incident could still occur.
“What distinguishes truly prepared organisations is their ability to detect threats early, respond swiftly and remediate issues without causing prolonged disruption to operations.
“In cybersecurity, we cannot wait until a crisis strikes before deciding who needs to take action,” she said.
Raja Azrina said cybersecurity was not a new field for TM, as it had long been part of the company’s responsibility to manage and protect the nation’s digital infrastructure.
“TM’s cybersecurity capabilities are built on years of experience in protecting our own operations and supporting the digital needs of enterprises and the government, covering networks, cloud services, data centres and applications,” she said.
“Our teams continuously monitor security, drawing on their experience in managing vast and complex digital environments,” she added.
She noted that TM also had local cybersecurity experts specialising in various areas, including threat detection and monitoring, incident response and digital forensics.
“Based on our experience, cybersecurity monitoring and controls are required at every level - network, infrastructure and application - to establish layered protection and enhance the effectiveness of detection and response,” she said.
For Raja Azrina, the question today is no longer whether organisations will adopt AI, but whether they can do so securely while maintaining the trust of customers and the public, as security measures must evolve as rapidly as technology.
She said this was one of the key reasons TM developed the TM Cyber Defence Centre (TM CYDEC).
Through a “Cyber Fusion” approach, TM CYDEC enables comprehensive monitoring of cybersecurity issues across network, infrastructure and application security for the industry and government sectors. TM also has an AI security framework in place to govern AI security.
“We believe that the right cybersecurity strategy, a risk-based approach, and effective services and technologies can help organisations detect and respond to cyber threats earlier, thereby minimising their impact on business.
“Ultimately, our goal is to enable organisations to continue innovating and leveraging AI with confidence, without compromising security and trust,” she said. — Bernama
.png)
3 hours ago
2




English (US) ·